JWT Decoder
Decode a JSON Web Token to read its header, payload and expiry.
Private by design. Your token and secret are processed only in this browser tab. Nothing is uploaded, stored or logged. Decoding is not verifying: anyone can read a JWT payload. Only a successful signature check, performed by your server with a trusted key, proves a token is genuine.
Encoded token
Paste a JSON Web Token. A leading Bearer prefix is fine.
Paste a token above, or press Load sample to see header, payload, claims, expiry and signature verification.
Header
The alg field is set from the algorithm below
Payload
Claims to include
Sign
HMAC signing with WebCrypto, locally
Algorithm
Generated token
Signing...
About this tool
A JSON Web Token (JWT) has three Base64URL-encoded parts: header, payload and signature. This tool decodes the header and payload, explains the claims, checks expiry, and can optionally verify an HMAC signature or build a test token.
How to use it
- Paste the token on the Decode tab.
- Read the colour-coded parts, the claims table and the expiry countdown.
- Optionally enter an HS256/384/512 secret to verify the signature.
- Use the Build tab to sign a test token.
Frequently asked questions
- Does this verify the token?
- Only if you enter an HMAC secret (HS256, HS384 or HS512), and that check runs in your browser. For other algorithms it only decodes. Production verification must be done on your server.
- Can I build a token here?
- Yes, for testing. Tokens built in the browser must never be used in production.
- Is it safe to paste a real token?
- Decoding runs locally in your browser. Even so, avoid pasting live production tokens into any website.